Table of Contents
An AML workflow is the structured process an organization uses to identify, assess, investigate, and report potential money-laundering risks.
It connects customer due diligence, risk assessment, sanctions screening, transaction monitoring, alert management, case investigation, escalation, regulatory reporting, and ongoing review. Each component may rely on a specialist system, but the overall workflow determines how information and decisions move between systems and people.
Detection is only part of the process. Once a screening or monitoring system identifies a potential risk, someone must assess the signal, gather evidence, document the analysis, decide whether escalation is necessary, and complete any required reporting within the applicable timeframe.
Without a coordinated AML workflow, these activities can become fragmented across inboxes, spreadsheets, document repositories, monitoring platforms, and compliance teams. That fragmentation can delay investigations and make it difficult to demonstrate how a decision was reached.
Key takeaways
An AML workflow covers the complete customer relationship. It begins with customer identification and risk assessment, continues through ongoing monitoring, and includes investigation, reporting, record retention, and periodic or event-driven review.
Monitoring is only one component. Transaction-monitoring and screening systems identify potential risk. The broader workflow determines who reviews each result and what happens next.
Risk should shape the process. Higher-risk customers and cases require additional information, closer monitoring, deeper investigation, or more senior review.
Every significant decision needs a documented rationale. Compliance teams should be able to show what information they reviewed, who made the decision, and why the selected outcome was appropriate.
Automation should support human judgment. Repetitive coordination can be automated, but qualified professionals should remain responsible for risk acceptance, case conclusions, and regulatory-reporting decisions.
What is an AML workflow?
An anti-money laundering workflow is a defined sequence of checks, tasks, decisions, reviews, and reporting activities used to manage financial-crime risk.
A typical workflow connects several areas:
- Customer identification and verification
- Customer and business risk assessment
- Sanctions, PEP, and adverse-media screening
- Customer due diligence or enhanced due diligence
- Ongoing transaction monitoring
- Alert triage and prioritization
- Case investigation and evidence collection
- Escalation and quality review
- Suspicious activity reporting
- Record retention and continuing review
These activities do not necessarily happen in one platform. Identity-verification providers, screening services, transaction-monitoring systems, case-management applications, regulatory filing systems, and workflow platforms may all contribute to the process.
The AML workflow is the operating framework that connects them.
AML workflow vs. KYC workflow vs. transaction monitoring
KYC, transaction monitoring, and case management are related parts of AML compliance, but they serve different purposes.
A KYC workflow establishes and maintains customer context. It collects and verifies information about the customer, beneficial owners, expected activity, source of funds, business purpose, and relevant risk factors. KYC is commonly associated with onboarding, but customer information may also require periodic or event-driven review.
A transaction-monitoring workflow evaluates activity. It compares transactions with rules, scenarios, behavioral patterns, customer profiles, or other risk indicators. Its purpose is to identify activity that may require review.
An AML case management workflow governs the investigation. It takes an alert, referral, or other signal through triage, assignment, evidence gathering, analysis, escalation, and resolution.
The broader AML workflow encompasses all three. Customer due diligence provides the context, monitoring identifies potential deviations, and case management coordinates the response.
The 10 steps of an AML workflow
The precise design varies by institution, customer type, product, and jurisdiction. However, most AML workflows contain the following stages.
1. Collect customer and business information
The workflow begins by gathering enough information to understand who the customer is and why the relationship is being established.
For an individual, this may include identifying information, contact details, occupation, expected account activity, and source of funds. For an organization, the process may also collect incorporation records, business activities, ownership information, authorized representatives, expected transaction patterns, and operating jurisdictions.
The required information should reflect the customer and relationship. A simple retail account and a multinational business with layered ownership should not automatically follow identical paths.
Structured collection reduces the need to chase missing information later and creates the foundation for downstream screening, risk assessment, and monitoring.
2. Verify identity and beneficial ownership
The organization checks the information supplied by the customer using appropriate documents, data sources, and verification methods.
The exact controls depend on the institution and jurisdiction. They may include document checks, database verification, biometric comparisons, business-registry searches, or manual review.
For legal entities, the workflow may also identify and verify beneficial owners and people who exercise significant control. If the ownership structure is unclear, contradictory, or unusually complex, the case may require additional information or enhanced review.
Verification tools can assist with document extraction and consistency checks, but their results should be handled according to the organization’s risk policies. A technology-generated match or score is an input—not necessarily a final decision.
3. Screen customers and related parties
Relevant customers, beneficial owners, directors, representatives, and counterparties may be screened against sanctions lists, politically exposed person data, internal watchlists, and other appropriate risk sources.
Adverse-media checks may also be used where required by policy or risk level.
Screening is not always a one-time onboarding activity. Customer information and external risk data change, so organizations may perform ongoing or event-driven rescreening.
A potential match must be reviewed in context. Similar names, incomplete identifiers, transliteration differences, and outdated records can create false positives. The workflow should define who reviews a match, what evidence is required, and when it must escalate.
4. Assess and classify customer risk
The organization evaluates the level of money-laundering and financial-crime risk associated with the relationship.
Factors may include the customer type, products used, delivery channels, ownership complexity, expected activity, geographic exposure, PEP status, source of funds, industry, and screening results.
The result determines how the remaining workflow operates. A higher-risk relationship may require additional evidence, more senior approval, enhanced monitoring, or shorter review intervals.
Risk scoring should not become an unexplained number. The underlying factors, changes, overrides, and final classification should remain visible and reviewable.
5. Apply customer due diligence or enhanced due diligence
Standard customer due diligence establishes the purpose and intended nature of the relationship and confirms that the organization understands the customer’s expected activity.
Higher-risk relationships may require enhanced due diligence. This can include deeper ownership research, additional source-of-funds or source-of-wealth evidence, more detailed business information, senior approval, or greater monitoring intensity.
The workflow should identify which conditions trigger enhanced due diligence, who must provide and review the evidence, and who can approve the relationship.
Missing information should trigger a defined exception path. It should not remain buried in an email chain or depend on an analyst remembering to follow up.
6. Monitor transactions and customer activity
Once the relationship is active, transaction-monitoring systems assess activity against defined scenarios, thresholds, behavioral patterns, and customer context.
The purpose is to identify activity that may be inconsistent with the customer’s known profile or indicative of financial-crime risk. Examples can include unusual changes in volume, rapid movement of funds, transactions involving higher-risk jurisdictions, apparent structuring, or activity with no clear economic purpose.
Not every deviation is suspicious. Businesses change, customers enter new markets, and legitimate transactions can resemble known risk patterns. Monitoring produces a signal that requires evaluation—not proof of money laundering.
Customer information must therefore remain accurate enough to make the comparison meaningful. If expected activity is outdated, monitoring results may produce unnecessary alerts or fail to reflect genuine risk.
7. Generate, triage, and prioritize alerts
When monitoring or screening identifies a potential concern, the alert enters a review queue.
Initial triage determines whether the alert is relevant, duplicated, clearly explainable, or in need of deeper investigation. The analyst may review the triggering activity, customer risk profile, prior alerts, transaction history, related entities, and available supporting information.
Risk-based prioritization helps direct attention to the alerts with the greatest potential exposure. Relevant factors can include customer risk, alert severity, sanctions exposure, transaction value, geographic risk, linked accounts, previous investigations, and whether potentially suspicious activity is continuing.
Every alert should have an owner, status, and due date. Even when an alert is closed without becoming a formal case, the disposition should include enough rationale to explain the decision.
8. Investigate the case and collect evidence
Alerts requiring deeper analysis move into an AML case management workflow.
The case should connect the originating alert, relevant transactions, customer context, previous findings, supporting documents, investigator notes, deadlines, and decision history.
Investigators may examine activity across a longer period, review relationships among accounts and entities, compare behavior with the customer’s expected activity, request information from internal teams, and assess the credibility of supporting explanations.
Evidence may include transaction records, onboarding documents, beneficial ownership information, invoices, contracts, customer communications, previous alerts, account relationships, screening results, and internal referrals.
The investigation should explain more than what happened. It should show what was reviewed, what the evidence indicated, which alternative explanations were considered, and how the investigator reached the recommendation.
This is where structured exception handling becomes important. Each request, handoff, review, and decision should remain connected to the case rather than scattered across separate communication channels.
9. Escalate, report, or close the case
After completing the investigation, the analyst recommends an outcome. Depending on the findings and institutional procedures, the case may close with documented rationale, require additional monitoring, move to enhanced review, escalate to senior compliance or legal, or proceed to a suspicious activity reporting determination.
The appropriate BSA officer, MLRO, compliance officer, or other authorized decision-maker should receive the evidence and analysis required to assess the recommendation. Higher-risk cases may also undergo an independent quality review.
When regulatory reporting is required, the workflow should manage preparation, review, approval, submission, and associated deadlines. It must also protect restricted information, including the confidentiality of SAR information where applicable.
In the United States, covered financial institutions generally must file a SAR within 30 calendar days after initially detecting facts that may constitute a basis for filing. When no suspect has been identified, the period may extend to 60 days. Importantly, the clock does not necessarily begin when an automated system first generates an alert. FinCEN explains that it begins when the institution knows or has reason to suspect the activity meets a reportable definition.
These requirements are jurisdiction-specific. Organizations should configure deadlines and escalation paths according to the regulations that apply to them.
If a case closes without reporting, the closure rationale should still explain what was reviewed and why the activity was reasonably explained or did not meet the applicable escalation criteria.
10. Retain records and continue monitoring
Closure does not end the AML lifecycle.
The organization must retain case records, supporting evidence, decisions, approvals, and filing information according to applicable requirements. Access should remain restricted to authorized users, and the case history should show who performed each significant action and when.
For US SARs, financial institutions are generally required to retain the filing and its supporting documentation for five years from the filing date. FinCEN provides additional guidance on SAR documentation and retention. Other jurisdictions and AML records may be subject to different periods.
The case outcome may also affect the customer’s risk rating, monitoring intensity, review schedule, or relationship status. Patterns identified across cases can inform monitoring adjustments, quality control, training, and broader risk assessments.
Common AML red flags and workflow triggers
A red flag is a reason to investigate further, not proof that money laundering has occurred. Its importance depends on customer context, transaction history, available evidence, and the combination of indicators present.
Activity inconsistent with the customer profile. Transaction volume, frequency, value, or counterparties differ materially from the customer’s stated business or established behavior.
Potential structuring. Transactions appear divided into smaller amounts in a way that may be intended to avoid a reporting or control threshold.
Rapid movement of funds. Money enters and leaves accounts quickly, passes through several entities, or follows a pattern without a clear business purpose.
Higher-risk geographic exposure. Activity involves jurisdictions associated with sanctions, strategic AML deficiencies, secrecy risks, or other relevant concerns.
Sanctions or PEP screening results. A customer or related party produces a potential match requiring review and possible escalation.
Adverse-media information. Credible reporting connects the customer or related parties with corruption, fraud, financial crime, or an investigation.
Complex or opaque ownership. Layered entities, nominee arrangements, unexplained intermediaries, or contradictory ownership information make control difficult to establish.
Unexpected changes in customer behavior. A dormant account becomes active, a customer begins using a new product or geography without explanation, or activity changes substantially after onboarding.
The workflow should help investigators examine these indicators together rather than treating each one as a standalone conclusion.
What makes an AML workflow effective?
Risk-based decision-making. The depth of due diligence, monitoring, investigation, and review should reflect the level and type of risk.
Clear ownership. Every task, alert, case, escalation, and approval needs an accountable person or role.
Consistent controls with room for judgment. Standard steps and evidence requirements improve consistency, but investigators must be able to adapt to the facts of a case.
Connected context. Reviewers need customer information, alert details, evidence, prior activity, notes, and decisions without reconstructing the history manually.
Defined escalation paths. Teams should know which conditions require senior review, legal involvement, enhanced controls, or regulatory reporting.
Visible deadlines. Internal service levels and applicable reporting timeframes should be monitored across the workflow, not left to personal calendars.
Complete decision records. A reliable history should capture evidence, analysis, approvals, changes, handoffs, and final rationale.
A broader compliance workflow applies the same principles: defined roles, controlled handoffs, deadlines, evidence, and documented decisions.
Where AML workflows commonly break down
Customer information becomes outdated. Monitoring decisions become less reliable when expected activity, ownership, business purpose, or customer risk has changed.
Systems operate in isolation. Screening, monitoring, customer data, evidence, and case decisions sit in separate platforms without a coordinated process.
Alerts lack ownership. Cases remain in queues because responsibility for the next action is unclear.
Evidence collection depends on email. Investigators repeatedly chase documents, lose context, or struggle to confirm which version was reviewed.
Every alert follows the same path. Low-risk alerts receive unnecessary effort while complex cases do not reach specialist reviewers quickly enough.
Decisions happen outside the case record. Reviewer comments and approvals remain in meetings, chats, or inboxes, weakening the formal history.
Deadline tracking is manual. Teams cannot easily see aging alerts, cases awaiting evidence, upcoming filing deadlines, or overdue reviews.
Closure notes are inadequate. The outcome is recorded, but the supporting reasoning is too brief to demonstrate how the decision was reached.
How to improve an AML workflow
Map the complete lifecycle. Document the process from information collection through ongoing review, including systems, roles, decision points, exceptions, and handoffs.
Define entry and exit criteria. Specify what allows a customer, alert, or case to move forward and what must be completed before each stage closes.
Route work by risk. Use customer risk, alert type, jurisdiction, severity, and required expertise to determine the appropriate path.
Standardize evidence requirements. Define the minimum information needed for each review type while allowing analysts to request more when the facts require it.
Set service levels and escalation rules. Establish internal targets for document collection, alert triage, investigation, quality review, and filing preparation.
Build quality control into the workflow. Route designated cases for independent or supervisory review and track recurring deficiencies.
Measure operational performance. Useful indicators include onboarding exceptions, screening-review time, alert age, case age, backlog by risk, time awaiting evidence, reassignment rates, review returns, and filing timeliness.
Where automation and AI can help
Workflow automation can reduce repetitive coordination while keeping accountable decisions with qualified professionals.
Data collection and validation can identify incomplete fields, inconsistent submissions, or missing documents before a review begins.
Routing and assignment can send work to the appropriate analyst according to risk, geography, customer type, or workload.
Evidence requests and reminders can prompt participants and display what remains outstanding.
Case summarization can help investigators navigate large volumes of information when the summary remains traceable to its sources and receives human verification.
Evidence organization can associate documents or data with the appropriate case and investigative question.
Draft assistance can help structure review notes or reporting narratives, but generated text must be checked against the underlying evidence.
Completeness checks can identify missing tasks, absent approvals, inconsistent fields, or unresolved questions before a case advances.
Automation should not silently change a customer risk rating, close an investigation, or make a regulatory-reporting decision without appropriate controls and oversight. AI use should account for data protection, access restrictions, model limitations, validation, explainability, and applicable regulatory expectations.
How Moxo supports AML workflows
AML programs depend on specialist systems for identity verification, screening, transaction monitoring, risk data, and regulatory filing. Moxo can orchestrate the human, document, review, and approval steps surrounding those systems.
During customer due diligence, structured workflows can coordinate document collection, internal reviews, exception handling, and approvals. Conditional paths can direct higher-risk relationships to enhanced due diligence or senior review while keeping routine cases moving.
When an alert requires investigation, an AML case investigation workflow can route the case to an appropriate analyst with the necessary context. Evidence requests, internal tasks, reviewer feedback, and approvals then remain connected to the process.
Automated reminders and escalation rules help move outstanding work forward. Status views give teams visibility into open requests, aging cases, reviews awaiting action, and workflow bottlenecks. A centralized activity history preserves the operational record of tasks, submissions, comments, decisions, and handoffs.
This extends compliance workflow automation across the coordination layer of the AML lifecycle. Moxo does not replace transaction-monitoring, screening, identity-verification, or regulatory filing systems. It helps connect their outputs to the people responsible for due diligence, investigation, review, and approval.
To explore how Moxo could support your AML workflow, explore the platform, start free, or book a demo.
AML workflow implementation checklist
Define the workflow boundary. Identify which AML processes, systems, teams, and jurisdictions are in scope.
Map every handoff. Document how information moves from onboarding and screening into monitoring, investigation, and reporting.
Assign ownership. Give every request, alert, case, review, and escalation an accountable role.
Connect risk to the path. Ensure higher-risk customers and cases receive proportionate due diligence and oversight.
Standardize required evidence. Specify what must be collected and reviewed at each stage.
Document decision criteria. Clarify who can approve, reject, escalate, close, or recommend reporting.
Configure deadlines carefully. Align internal targets and escalations with applicable regulatory obligations.
Protect sensitive information. Apply appropriate access controls, confidentiality measures, and retention policies.
Preserve the complete history. Keep evidence, actions, reviews, decisions, and timestamps connected.
Use outcomes to improve controls. Feed investigation findings into customer risk, monitoring, training, and quality assurance.
Build a more connected AML workflow
An effective AML program does more than generate alerts. It establishes a controlled path for collecting customer information, evaluating risk, monitoring activity, investigating concerns, making accountable decisions, and maintaining the records that support those decisions.
The strongest AML workflows combine specialist detection systems with clear ownership, risk-based routing, consistent evidence requirements, structured human review, and reliable documentation.
Automation can remove administrative friction, but it should strengthen—not obscure—human accountability. Compliance professionals remain responsible for understanding the evidence, applying the institution’s policies, and making defensible decisions.
Moxo helps coordinate these human and document-driven steps while existing AML systems continue to perform specialist verification, screening, monitoring, and filing functions. Book a demo to see how a structured workflow could connect your AML operations from intake through resolution.
Frequently asked questions
What is an AML workflow?
An AML workflow is the structured sequence used to identify, assess, monitor, investigate, and report potential money-laundering risks. It can include customer due diligence, screening, customer risk assessment, transaction monitoring, alert triage, case investigation, escalation, reporting, and ongoing review.
What are the main steps in an AML workflow?
The main steps are collecting customer information, verifying identity and ownership, screening relevant parties, assessing customer risk, completing due diligence, monitoring activity, triaging alerts, investigating cases, escalating or reporting concerns, and retaining records for ongoing review.
What is an AML case management workflow?
An AML case management workflow is the investigation component of the broader AML process. It moves alerts or referrals through triage, assignment, evidence collection, analysis, review, escalation, regulatory-reporting decisions, and closure.
What is the difference between KYC and AML?
KYC establishes and maintains information about the customer, including identity, ownership, business purpose, and expected activity. AML is the broader framework that uses this information alongside screening, monitoring, investigation, and reporting to manage money-laundering and financial-crime risk.
What is the difference between an AML alert and a case?
An alert is a signal generated by monitoring, screening, or another control. A case is the formal investigation record created when that signal requires deeper analysis, evidence collection, documented decisions, or escalation.
How long does an AML investigation take?
There is no universal duration. Straightforward cases may be resolved quickly, while investigations involving multiple entities, jurisdictions, accounts, or evidence requests may take considerably longer. The workflow should account for complexity and applicable reporting deadlines.
When must a SAR be filed?
In the United States, covered financial institutions generally file within 30 calendar days after initially detecting facts that may constitute a filing basis. When no suspect has been identified, the deadline may extend to 60 days. Rules differ by institution and jurisdiction.
Can AI make AML decisions?
AI can assist with data extraction, prioritization, summaries, evidence organization, drafting, and completeness checks. Qualified professionals should retain responsibility for material risk decisions, investigative conclusions, case closure, and regulatory reporting.

